Trade: business regulation; requirements and safety standards for developers of certain artificial intelligence models; provide for. Creates new act.
Michigan House Bill 4668, the 'Artificial Intelligence Safety and Security Transparency Act,' targets large AI developers—defined as entities that have spent at least $5 million in compute on a single foundation model and at least $100 million across all foundation models in the preceding 12 months—and imposes safety, transparency, and whistleblower-protection requirements effective January 1, 2026. Section 3 defines key terms including 'critical risk' (a foreseeable, material risk of death or serious injury to more than 100 people, or more than $1 billion in damages, from CBRN weapons, AI-assisted cyberattacks, or autonomous criminal conduct), 'foundation model,' and 'large developer.' Section 5 requires large developers to maintain detailed 'safety and security protocols' covering risk thresholds, testing procedures, deployment decisions, security protections, safeguards, incident response, and third-party roles. Section 7 requires large developers to publish their safety and security protocols conspicuously, publish material modifications within 30 days, publish transparency reports at least every 90 days covering a specified reporting window, and retain test records for 5 years; it also prohibits false or materially misleading statements in required documents and governs permissible redactions (for trade secrets, public safety, or national security), with unredacted versions available to the attorney general on request. Section 9 requires an independent annual audit by a reputable third-party auditor with both corporate compliance and technical foundation-model safety expertise, assessing protocol compliance and any disclosure violations; the audit report must be published within 90 days. Section 11 provides whistleblower protections for employees—including contractors, subcontractors, unpaid advisors, and corporate officers—who report critical risks, allowing civil actions for injunctive relief, actual damages, attorney fees, and reinstatement within 90 days of a violation; large developers must maintain internal anonymous disclosure processes and retain records for 7 years; violations carry a civil fine of up to $500. Section 13 empowers the attorney general to bring civil actions for violations of Sections 7 or 9, seeking fines up to $1 million per violation, injunctive or declaratory relief, or injunctive relief for imminent critical risks.
Status history
Current status as of 2025-06-24
In committee
2025-06-24
observed 2026-10-03
Impact areas
- Workforce Impacts
- Enterprise Adoption
- Quality Assurance
- AI Policy